Skip to content
← Back

Data Processing Agreement

Last updated 1 August 2026 · for employers using the ATS

This agreement governs the personal data that Anakalice processes on an employer's behalf when the employer uses the ATS to run its hiring. It forms part of the Terms of Service and is written so a real employer can understand exactly what we do with their applicants' data, and what we don't.

The two roles, kept strictly separate

For the recruitment data an employer collects through the ATS, the employer is the data controller and Anakalice is the data processor, acting only on the employer's documented instructions.

Separately, Anakalice remains its own independent controller, not the employer's processor, for user accounts and authentication, platform security and fraud prevention, moderation of public jobs, trust evidence records, audit and system logs, and its own legal-compliance obligations. This separation is deliberate. It is what lets Anakalice keep an honest, tamper-resistant safety and audit record independent of any single employer.

What Anakalice is instructed to do

The employer instructs Anakalice to process the controlled recruitment data only to provide the ATS: receiving and recording applications, storing applicant information and CVs, displaying applicants to the employer's authorised users, sending transactional email notifications, supporting the hiring-pipeline workflow, storing the employer's notes and ratings, producing requested exports, backing up data for disaster recovery, and keeping the service secure. Anakalice will not use controlled recruitment data for any other purpose.

The data involved

Applicant name and contact details; CV and its metadata; cover letter, experience, expected salary, notice period, and profile links; the application record and its hiring stage; and the employer's own notes and decisions about applicants. The subjects are the employer's job applicants and candidates. The platform does not request special-category data.

Security measures

We apply real controls: passwords stored only as secure one-way hashes; the service served over HTTPS with cross-site-request-forgery protection; uploaded CVs stored with randomised names outside the public web folder and served only to authorised users; tenant isolation separating each employer's data from every other's; and audit logging that stores personal data by reference so it can be redacted on erasure. Staff reach a tenant's data only through deliberate, logged administrative action.

We are honest about our limits. Anakalice does not currently hold ISO 27001 or SOC 2 certification and does not claim to, and the current shared-hosting environment limits some controls. Planned improvements are tracked in our security roadmap.

Sub-processors

The employer gives general authorisation for Anakalice to use sub-processors to provide the service; Anakalice remains responsible for their acts. We use providers in these categories: hosting, email delivery, domain/DNS, and disaster-recovery backups. We will give reasonable notice of any intended change so the employer can object on reasonable data-protection grounds.

Data-subject requests and breaches

Anakalice will assist the employer, so far as the platform allows, to respond to applicants' requests to access, correct, or delete their data. If an applicant contacts us directly about data the employer controls, we will refer or forward the request to the employer. Because Anakalice is the processor here, the employer (as controller) is the party that notifies the regulator and affected people about a breach of controlled data; on becoming aware of such a breach, Anakalice will notify the employer without undue delay with the information they reasonably need, and will help contain and investigate it.

Deleting data

On termination or on the employer's instruction, Anakalice will delete or return the employer's controlled recruitment data within 30 days, after which working copies are deleted and backups age out per our retention schedule. Deleting the employer's ATS data does not delete Anakalice's own independent-controller records (audit logs, trust-evidence, and security logs), which reference personal data by ID and are redactable. Where an individual exercises erasure, the personal detail is redacted while the fact that an action occurred is preserved. This is intentional and keeps the safety trail honest.

Law and changes

This agreement is governed by the laws of the Federal Republic of Nigeria, including the Nigeria Data Protection Act 2023, and lasts as long as Anakalice processes controlled recruitment data for the employer. If we update it materially, we will notify ATS customers. Questions? Email info@anakaliceacademy.com.ng.